Legal
Last updated: 5 July 2026
This is a translation of the Dutch original. In case of any discrepancy, the Dutch version prevails.
This data processing agreement (verwerkersovereenkomst) belongs to and forms part of the agreement between the parties ("Main Agreement") and governs the processing of personal data in accordance with article 28 GDPR (AVG).
1.1 Processor processes personal data solely for the purpose of performing the Main Agreement (the Scan, the Build (Uitvoering) and/or Care (Beheer)) and solely on the basis of written, documented instructions from Controller.
1.2 Processor does not process the data for its own purposes and does not provide it to third parties, except as governed here or as required by law.
1.3 The subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
2.1 Processor processes personal data only on the instructions of Controller, unless a statutory obligation provides otherwise; in that case Processor notifies this in advance, unless that law prohibits it.
2.2 Processor informs Controller if, in its opinion, an instruction infringes the GDPR (AVG) or other privacy legislation.
3.1 Processor binds persons who have access to the personal data to confidentiality.
3.2 Access is limited to persons for whom this is necessary for the performance of the Main Agreement.
4.1 Processor takes appropriate technical and organisational measures in accordance with article 32 GDPR (AVG). The measures are set out in Annex 2.
4.2 Access to Controller's systems is read-only and is used solely for the agreed analysis.
5.1 Controller gives Processor general authorisation to engage the sub-processors listed in Annex 3.
5.2 Processor imposes on these sub-processors the same obligations as those set out in this Data Processing Agreement.
5.3 Processor informs Controller in advance of intended changes to the sub-processors, so that Controller can object.
5.4 Processor remains fully liable to Controller for compliance by sub-processors.
6.1 Processor provides reasonable cooperation with requests from data subjects (access, rectification, erasure, restriction, objection, data portability) and forwards requests it receives directly to Controller.
6.2 Processor provides reasonable assistance with a data protection impact assessment (DPIA) and with prior consultation of the supervisory authority.
7.1 Processor informs Controller without undue delay, and at the latest within 48 hours of discovery, of a personal data breach.
7.2 The notification contains at least the nature of the breach, the data and categories concerned, the likely consequences and the measures taken or proposed.
7.3 Notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and/or data subjects remains the responsibility of Controller.
8.1 Transfers of personal data outside the European Economic Area take place only with appropriate safeguards, such as the European Commission's standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.
8.2 For the AI processing, a standard log retention of no more than 7 days for abuse detection applies at the sub-processor concerned; input and output are not used for model training.
9.1 After termination of the Main Agreement, Processor deletes or returns, at Controller's option, all personal data, and deletes existing copies, unless retention is required by law.
9.2 Processor confirms the deletion in writing upon request.
10.1 Upon request, Processor makes available the information needed to demonstrate compliance with article 28 GDPR (AVG).
10.2 Controller may, at most once a year and with reasonable notice, carry out (or have carried out) an audit. The reasonable costs thereof are for Controller's account, unless the audit reveals a material shortcoming.
11.1 The liability regime set out in the Main Agreement and the terms and conditions (algemene voorwaarden) applies mutatis mutandis to liability under this Data Processing Agreement, including the limitations and the maximum amount contained therein.
11.2 Controller is responsible for the lawfulness of the processing, including a valid legal basis, informing data subjects and, where required, a data protection impact assessment. Fines, claims from data subjects or from the supervisory authority arising from the absence thereof or from Controller's instructions are for Controller's account. Controller indemnifies Processor against such claims.
11.3 This Data Processing Agreement applies for as long as Processor processes personal data for Controller and ends with the Main Agreement.
11.4 Dutch law applies to this Data Processing Agreement.
| Sub-processor | Function | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Server/hosting | Germany (EU) | Not applicable (within EU) |
| Supabase | Database and file storage | EU (eu-west-1) | Not applicable (within EU) |
| Vercel Inc. | Hosting/delivery of website | US (EU edge) | Standard contractual clauses / Data Privacy Framework |
| Resend | E-mail sending | US | Standard contractual clauses / Data Privacy Framework |
| AI model provider (e.g. Anthropic, OpenAI, EU alternative) | AI processing (analysis) | EU/US | Standard contractual clauses; no model training; short or no log retention; client is informed in advance |
| Google (Cloud / Drive API) | Storage of deliverables + read-only access after consent | EU/US | Standard contractual clauses / Data Privacy Framework |